Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack. | |
Title | Elastic Defend Insertion of Sensitive Information into Log Files | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-04-09T19:28:32.185Z
Reserved: 2025-01-31T15:28:16.917Z
Link: CVE-2025-25013

Updated: 2025-04-09T19:28:10.773Z

Status : Awaiting Analysis
Published: 2025-04-08T23:15:45.540
Modified: 2025-04-09T20:02:41.860
Link: CVE-2025-25013

No data.